WS_FTP Server Directory Traversal
CVE-2023-42657

9.9CRITICAL

Key Information:

Vendor
CVE Published:
27 September 2023

Summary

A directory traversal vulnerability exists in WS_FTP Server versions prior to 8.7.4 and 8.8.2, allowing attackers to perform unauthorized file operations. Attackers can exploit this flaw to access and manipulate files and directories beyond their designated WS_FTP folder path, potentially leading to the deletion, renaming, creation, or removal of files and folders within the underlying operating system.

Affected Version(s)

WS_FTP Server 8.8.0

WS_FTP Server 8.8.0 < 8.8.2

WS_FTP Server 8.7.0 < 8.7.4

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.